使用管理工具的網路原則伺服器管理Network Policy Server Management with Administration Tools

適用於:Windows Server(以每年次管道)、Windows Server 2016Applies To: Windows Server (Semi-Annual Channel), Windows Server 2016

若要深入了解您可以使用管理 NPS 伺服器工具,您可以使用此主題。You can use this topic to learn about the tools that you can use to manage your NPS servers.

NPS 安裝之後,您可以管理 NPS 伺服器:After you install NPS, you can administer NPS servers:

  • 本機,來使用 NPS NPS Microsoft Management Console (MMC) 嵌入式管理單元,靜態 NPS 主控台系統管理工具,Windows PowerShell 命令,或網路殼層 (Netsh) 命令。Locally, by using the NPS Microsoft Management Console (MMC) snap-in, the static NPS console in Administrative Tools, Windows PowerShell commands, or the Network Shell (Netsh) commands for NPS.
  • 從遠端 NPS 伺服器、NPS,或遠端桌面連接使用 NPS MMC 嵌入式管理單元、NPS Netsh 命令、的 Windows PowerShell 命令。From a remote NPS server, by using the NPS MMC snap-in, the Netsh commands for NPS, the Windows PowerShell commands for NPS, or Remote Desktop Connection.
  • 從遠端工作站,藉由組合與其他工具,例如 NPS MMC 或 Windows PowerShell 中使用遠端桌面連接。From a remote workstation, by using Remote Desktop Connection in combination with other tools, such as the NPS MMC or Windows PowerShell.

注意

在 Windows Server 2016,您可以使用 NPS 主控台管理 NPS 本機伺服器。In Windows Server 2016, you can manage the local NPS server by using the NPS console. 若要管理遠端和本機 NPS 伺服器,您必須使用 NPS MMC snap\ 中。To manage both remote and local NPS servers, you must use the NPS MMC snap-in.

下列章節提供如何管理您的本機與遠端 NPS 伺服器上的指示。The following sections provide instructions on how to manage your local and remote NPS servers.

使用 NPS 主機設定 NPS 本機伺服器Configure the Local NPS Server by Using the NPS Console

您已安裝 NPS 之後,您可以使用此程序使用 NPS MMC 管理 NPS 本機伺服器。After you have installed NPS, you can use this procedure to manage the local NPS server by using the NPS MMC.

管理認證Administrative Credentials

若要完成此程序,您必須是系統管理員群組成員。To complete this procedure, you must be a member of the Administrators group.

藉由使用 NPS 主機設定 NPS 本機伺服器To configure the local NPS server by using the NPS console

  1. 在伺服器管理員中,按一下 [工具,然後按的網路原則伺服器In Server Manager, click Tools, and then click Network Policy Server. NPS 主控台開啟。The NPS console opens.

  2. 在 [NPS 主控台中,按一下 [NPS (Local)。In the NPS console, click NPS (Local). 在詳細資料窗格中,選擇標準設定進階設定,然後執行下列其中一個動作,根據您的選取項目:In the details pane, choose either Standard Configuration or Advanced Configuration, and then do one of the following based upon your selection:

    • 如果您選擇 [標準設定,從清單中,選取案例,然後依照 [[開始] 設定精靈的指示。If you choose Standard Configuration, select a scenario from the list, and then follow the instructions to start a configuration wizard.
    • 如果您選擇 [進階設定,按一下 [的箭號來展開進階設定選項,然後檢視並設定可用的選項,根據您想要-NPS 功能 RADIUS 伺服器、RADIUS proxy,或兩者。If you choose Advanced Configuration, click the arrow to expand Advanced Configuration options, and then review and configure the available options based on the NPS functionality that you want - RADIUS server, RADIUS proxy, or both.

使用 NPS MMC Snap\ 中管理多個 NPS 伺服器Manage Multiple NPS Servers by Using the NPS MMC Snap-in

您可以使用此程序使用 NPS MMC snap\ 在本機伺服器 NPS 和多個的 NPS 遠端伺服器管理。You can use this procedure to manage the local NPS server and multiple remote NPS servers by using the NPS MMC snap-in.

之前,請先執行下列程序,您必須在本機電腦上,並在遠端電腦上安裝 NPS。Before performing the procedure below, you must install NPS on the local computer and on remote computers.

根據網路條件和您使用 NPS MMC snap\ 中管理 NPS 伺服器數目,可能會很慢 MMC snap\ 中的回應。Depending on network conditions and the number of NPS servers you manage by using the NPS MMC snap-in, response of the MMC snap-in might be slow. 此外,NPS 伺服器設定流量在網路上的遠端管理工作階段使用傳送 NPS snap\ 中。In addition, NPS server configuration traffic is sent over the network during a remote administration session by using the NPS snap-in. 請確定您的網路都是安全實際及惡意使用者不擁有的存取權的網路流量。Ensure that your network is physically secure and that malicious users do not have access to this network traffic.

管理認證Administrative Credentials

若要完成此程序,您必須是系統管理員群組成員。To complete this procedure, you must be a member of the Administrators group.

使用 snap\ 中 NPS 管理多個 NPS 伺服器To manage multiple NPS servers by using the NPS snap-in

  1. 若要打開 MMC,系統管理員身分執行 Windows PowerShell。To open the MMC, run Windows PowerShell as an Administrator. Windows PowerShell 中,輸入mmc,然後按 ENTER 鍵。In Windows PowerShell, type mmc, and then press ENTER. Microsoft Management Console 開啟。The Microsoft Management Console opens.
  2. 在 MMC,在檔案功能表中,按一下 [新增/移除 Snap\ 在In the MMC, on the File menu, click Add/Remove Snap-in. [新增或移除 Snap\ 單元對話方塊。The Add or Remove Snap-ins dialog box opens.
  3. 新增或移除 Snap\ 單元,請在可用 snap\ 管理單元]、向下捲動清單、按一下 [的網路原則伺服器,,然後按一下 [新增In Add or Remove Snap-ins, in Available snap-ins, scroll down the list, click Network Policy Server, and then click Add. 選擇電腦對話方塊。The Select Computer dialog box opens.
  4. 選擇電腦,確認本機電腦 \(的電腦上的此主控台 running\)已選取,然後按一下 [ [確定]In Select Computer, verify that Local computer (the computer on which this console is running) is selected, and then click OK. Snap\ 在本機伺服器 NPS 新增到清單中選取 snap\ 單元The snap-in for the local NPS server is added to the list in Selected snap-ins.
  5. 新增或移除 Snap\ 單元,請在可用 snap\ 管理單元],確保網路原則伺服器是仍然選取,然後再按一下新增In Add or Remove Snap-ins, in Available snap-ins, ensure that Network Policy Server is still selected, and then click Add. 選擇電腦對話方塊再試一次。The Select Computer dialog box opens again.
  6. 選擇電腦,按一下 [另一部電腦,然後輸入 IP 位址的完整的網域名稱 (FQDN) 遠端 NPS 伺服器您想要使用 snap\ 中 NPS 管理。In Select Computer, click Another computer, and then type the IP address or fully qualified domain name (FQDN) of the remote NPS server that you want to manage by using the NPS snap-in. 或者,您可以按一下瀏覽]以仔細 directory 您想要新增的電腦。Optionally, you can click Browse to peruse the directory for the computer that you want to add. 按一下[確定]Click OK.
  7. 重複執行步驟 5 和 6 到 NPS snap\ 中新增更多 NPS 伺服器。Repeat steps 5 and 6 to add more NPS servers to the NPS snap-in. 完成新增所有 NPS 伺服器您想要管理,請按一下[確定]When you have added all the NPS servers you want to manage, click OK.
  8. 若要儲存更新使用 NPS 嵌入式管理單元,按一下 [檔案,然後按一下 [儲存To save the NPS snap-in for later use, click File, and then click Save. 另存新檔對話方塊中,瀏覽至您想要儲存的檔案,輸入您的 Microsoft Management Console (.msc) 檔案的名稱,然後按一下硬碟位置儲存In the Save As dialog box, browse to the hard disk location where you want to save the file, type a name for your Microsoft Management Console (.msc) file, and then click Save.

使用遠端桌面連接管理 NPS 伺服器Manage an NPS Server by Using Remote Desktop Connection

您可以使用此程序 NPS 遠端伺服器管理使用遠端桌面連接。You can use this procedure to manage a remote NPS server by using Remote Desktop Connection.

使用遠端桌面連接,您可以從遠端管理執行 Windows Server 2016 NPS 伺服器。By using Remote Desktop Connection, you can remotely manage your NPS servers running Windows Server 2016. 您也可以從遠端可以管理 NPS 伺服器執行 Windows 10 或較舊版本的 Windows client 作業系統的電腦。You can also remotely manage NPS servers from a computer running Windows 10 or earlier Windows client operating systems.

您可以使用遠端桌面連接到使用兩種方法來管理多個 NPS 伺服器。You can use Remote Desktop connection to manage multiple NPS servers by using one of two methods.

  1. 排列建立遠端桌面連接到每個 NPS 伺服器。Create a Remote Desktop connection to each of your NPS servers individually.
  2. 連接一 NPS 伺服器,請使用遠端桌面,然後使用該伺服器上 NPS MMC 管理其他遠端伺服器。Use Remote Desktop to connect to one NPS server, and then use the NPS MMC on that server to manage other remote servers. 如需詳細資訊,請查看一節使用 NPS MMC Snap\ 中管理多個 NPS 伺服器For more information, see the previous section Manage Multiple NPS Servers by Using the NPS MMC Snap-in.

管理認證Administrative Credentials

若要完成此程序,您必須是 NPS 伺服器上的系統管理員群組成員。To complete this procedure, you must be a member of the Administrators group on the NPS server.

使用遠端桌面連接管理 NPS 伺服器To manage an NPS server by using Remote Desktop Connection

  1. 在每個 NPS 伺服器您想要管理遠端電腦上,在伺服器管理員中,選取 [本機伺服器On each NPS server that you want to manage remotely, in Server Manager, select Local Server. 在伺服器管理員詳細資料窗格中,檢視遠端桌面設定,然後執行下列其中一項。In the Server Manager details pane, view the Remote Desktop setting, and do one of the following.
    1. 如果的值遠端桌面設定啟用,您不需要的一些步驟執行這個程序中。If the value of the Remote Desktop setting is Enabled, you do not need to perform some of the steps in this procedure. 跳到 [開始] 設定遠端桌面使用者權限來執行「步驟 4。Skip down to Step 4 to start configuring Remote Desktop User permissions.
    2. 如果遠端桌面設定已停用,按一下 [word停用If the Remote Desktop setting is Disabled, click the word Disabled. 系統屬性對話方塊在遠端索引標籤。The System Properties dialog box opens on the Remote tab.
  2. 遠端桌面,按一下 [可讓遠端連接到這部電腦In Remote Desktop, click Allow remote connections to this computer. 遠端桌面連接對話方塊。The Remote Desktop Connection dialog box opens. 執行下列其中一個動作。Do one of the following.
    1. 自訂允許網路連接,請按一下Windows 防火牆進階安全性與,然後設定允許您想要的設定。To customize the network connections that are allowed, click Windows Firewall with Advanced Security, and then configure the settings that you want to allow.
    2. 若要讓遠端桌面連接,針對所有網路連接的電腦上,按一下 [ [確定]To enable Remote Desktop Connection for all network connections on the computer, click OK.
  3. 系統屬性,請在遠端桌面,可以選擇是否要讓允許只有來自電腦執行遠端桌面與網路層級驗證,,讓您的選擇。In System Properties, in Remote Desktop, decide whether to enable Allow connections only from computers running Remote Desktop with Network Level Authentication, and make your selection.
  4. 按一下選取 [使用者]Click Select Users. 遠端桌面使用者對話方塊。The Remote Desktop Users dialog box opens.
  5. 遠端桌面使用者,以授予權限來連接遠端伺服器 NPS,請按一下 [使用者新增,然後輸入帳號的使用者名稱。In Remote Desktop Users, to grant permission to a user to connect remotely to the NPS server, click Add, and then type the user name for the user's account. 按一下[確定]Click OK.
  6. 重複執行「步驟 5 為每個您要 NPS server 的遠端存取權限授與的使用者。Repeat step 5 for each user for whom you want to grant remote access permission to the NPS server. 當您完成時新增的使用者時,請按一下[確定]以關閉 [遠端桌面使用者對話方塊和[確定]再試一次以關閉 [系統屬性] 對話方塊。When you're done adding users, click OK to close the Remote Desktop Users dialog box and OK again to close the System Properties dialog box.
  7. 若要連接到您所使用的上一個步驟來設定遠端 NPS 伺服器,請按一下[開始],向下捲動排序清單,然後按Windows 附屬應用程式,並按一下 [遠端桌面連接To connect to a remote NPS server that you have configured by using the previous steps, click Start, scroll down the alphabetical list and then click Windows Accessories, and click Remote Desktop Connection. 遠端桌面連接對話方塊。The Remote Desktop Connection dialog box opens.
  8. 遠端桌面連接對話方塊中,在電腦,輸入 NPS 伺服器名稱或 IP 位址。In the Remote Desktop Connection dialog box, in Computer, type the NPS server name or IP address. 如果您想要的話,請按一下選項,設定連接其他選項],然後按儲存儲存連接重複使用。If you prefer, click Options, configure additional connection options, and then click Save to save the connection for repeated use.
  9. 按一下連接,以及出現提示時提供的權限來登入並設定 NPS 伺服器 account 使用者 account 認證。Click Connect, and when prompted provide user account credentials for an account that has permissions to log on to and configure the NPS server.

使用 Netsh NPS 命令來管理 NPS 伺服器Use Netsh NPS commands to manage an NPS Server

顯示及計量] 與稽核使用同時 NPS 並遠端存取服務資料庫設定的驗證,驗證,設定,您可以 Netsh NPS 環境中使用的命令。You can use commands in the Netsh NPS context to show and set the configuration of the authentication, authorization, accounting, and auditing database used both by NPS and the Remote Access service. 使用命令來 Netsh NPS 操作:Use commands in the Netsh NPS context to:

  • 設定,或重新設定 NPS 伺服器,包括 NPS 的也適用於設定 Windows 介面中使用 NPS 主機的各個層面。Configure or reconfigure an NPS server, including all aspects of NPS that are also available for configuration by using the NPS console in the Windows interface.
  • 匯出一個 NPS 伺服器(來源),包括登錄和 NPS 設定存放區,做為 Netsh 指令碼的設定。Export the configuration of one NPS server (the source server), including registry keys and the NPS configuration store, as a Netsh script.
  • 使用 Netsh 指令碼,並從來源 NPS 伺服器匯出的設定檔到另一個 NPS 伺服器匯入的設定。Import the configuration to another NPS server by using a Netsh script and the exported configuration file from the source NPS server.

您可以從 Windows Server 2016 命令提示字元或 Windows PowerShell 來執行下列命令。You can run these commands from the Windows Server 2016 Command Prompt or from Windows PowerShell. 您也可以執行 netsh nps 命令指令碼與「批次檔案中。You can also run netsh nps commands in scripts and batch files.

管理認證Administrative Credentials

若要執行此程序,您必須使用本機電腦上的系統管理員群組成員。To perform this procedure, you must be a member of the Administrators group on the local computer.

NPS 伺服器上輸入 Netsh NPS 操作To enter the Netsh NPS context on an NPS server

  1. 命令提示字元」或「Windows PowerShell 開放。Open Command Prompt or Windows PowerShell.
  2. 輸入netsh,然後按 ENTER 鍵。Type netsh, and then press ENTER.
  3. 輸入nps,然後按 ENTER 鍵。Type nps, and then press ENTER.
  4. 若要檢視可用的命令的清單,輸入問號 (?) 並按下 ENTER。To view a list of available commands, type a question mark (?) and press ENTER.

如需 NPS Netsh 命令,查看在 Windows Server 2008 的網路原則伺服器 Netsh 命令,或下載整個Netsh 技術參考從 TechNet 主題館。For more information about Netsh NPS commands, see Netsh Commands for Network Policy Server in Windows Server 2008, or download the entire Netsh Technical Reference from TechNet Gallery. 此下載是完整網路殼層技術參考適用於 Windows Server 2008 和 Windows Server 2008 R2。This download is the full Network Shell Technical Reference for Windows Server 2008 and Windows Server 2008 R2. 格式不 zip 檔案中的 Windows 協助 (.chm)。The format is Windows Help (.chm) in a zip file. 要這些指令,仍然會出現在 Windows Server 2016 和 Windows 10,可讓您使用 netsh 這些的環境中,建議您使用 Windows PowerShell 雖然。These commands are still present in Windows Server 2016 and Windows 10, so you can use netsh in these environments, although using Windows PowerShell is recommended.

使用 Windows PowerShell 來管理 NPS 伺服器Use Windows PowerShell to manage NPS servers

您可以使用 Windows PowerShell 命令來管理 NPS 伺服器。You can use Windows PowerShell commands to manage NPS servers. 如需詳細資訊,下列 Windows PowerShell 命令參考主題。For more information, see the following Windows PowerShell command reference topics.

如需 NPS 管理的詳細資訊,請查看管理的網路原則 Server (NPS)For more information about NPS administration, see Manage Network Policy Server (NPS).